Cyber Security News

15 TP-Link Omada Flaws Exploit Zero-Touch Provisioning to Hijack Devices and Infiltrate Networks

Security researchers have disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem, which can be exploited to hijack devices, compromise controllers, expose credentials, and create access points into internal networks.

The research, titled “Zero Day Provisioning,” was presented at Black Hat USA 2026 and focuses on weaknesses in the trust relationships that enable Omada controllers to automatically configure gateways, routers, switches, and wireless access points.

TP-Link has issued advisories for multiple CVEs, while four findings were addressed outside the CVE process.

ZTP is designed to simplify large-scale deployments by allowing newly connected devices to identify their controller, authenticate, receive configuration data, and accept firmware or policy changes without requiring hands-on administration.

However, Forescout identified flaws in Omada’s onboarding and communication processes, including client-side code execution vulnerabilities, sensitive information disclosure, device spoofing, hijacking, and the compromise of encrypted communications.

The impact is not limited to Omada controllers and infrastructure devices; it also affects certain Festa products, VIGI surveillance platforms, TP-Link cloud services, and Android applications, including Tapo, Kasa, Omada, and Tether.

Several defects undermine the cryptographic chain of trust. CVE-2025-15627 involves a hard-coded private key in version 1 of the Omada protocol, while CVE-2025-15628 pertains to a hard-coded TLS certificate and its associated private key in version 2.

CVE-2025-15629 arises from a predictable RC4 encryption key, and CVE-2025-9291 highlights insufficient Common Name validation when devices verify controller certificates.

Collectively, these weaknesses could allow a knowledgeable adversary to impersonate trusted components or intercept supposedly secure traffic.

The most critical attack path begins before a device is fully enrolled. Researchers noted that threat actors could enumerate predictable serial numbers, retrieve related device information, and identify systems awaiting cloud adoption.

By spoofing a target device’s MAC address and exploiting a cloud-adoption race condition tracked as CVE-2025-15630, an attacker could obtain provisioning material meant for legitimate devices. Vulnerabilities related to default adoption credentials and insecure credential handling could further expose site credentials, administrator hashes, and potentially VPN secrets.

Forescout also identified CVE-2025-9289, a cross-channel scripting issue in Omada controller interfaces, and CVE-2025-9292, which involves an overly permissive web security policy under specific conditions.

An attacker who gains access could inject malicious JavaScript, trick an administrator into entering credentials, and use the stolen access to modify managed infrastructure.

Combined with previously disclosed TP-Link command-injection vulnerabilities, CVE-2025-7850 and CVE-2025-7851, these flaws could lead to a pathway from external device discovery to internal network access.

CVE / FindingVulnerability
CVE-2025-9289Cross-channel scripting in Omada controller web interface
CVE-2025-9290Non-unique or empty salts enable static credential hashes
CVE-2025-9291Insufficient certificate Common Name validation
CVE-2025-9292Permissive CSP enables cross-origin access-control bypass
CVE-2025-9293Insufficient certificate validation in TP-Link Android apps
CVE-2025-15544Weak protection of site credentials during device adoption
CVE-2025-15627Hard-coded private key in Omada protocol version 1
CVE-2025-15628Hard-coded TLS certificate and private key in protocol version 2
CVE-2025-15629Predictable / low-entropy RC4 key in protocol version 1
CVE-2025-15630Cloud device-adoption race condition
CVE-2025-15631Unsalted MD5 device-management password hashes protected with a hard-coded key
FSCT-2025-0003Unadopted devices can be adopted using serial numbers
FSCT-2025-0008Adoption challenges signed using default credentials
FSCT-2025-0011Predictable sequential serial numbers expose device information
FSCT-2025-0014Arbitrary-file upload and retrieval via unauthenticated temporary links

Organizations using Omada are advised to update affected device firmware, controller software, and mobile applications according to TP-Link’s advisories.

Administrators should also replace shared provisioning passwords with strong, unique credentials, enable multifactor authentication for TP-Link cloud accounts where available, rotate possibly exposed VPN keys and certificates, and ensure controllers are not directly exposed to the internet.

Implementing network segmentation, 802.1X with Network Access Control (NAC), port security, dynamic ARP inspection, wireless client isolation, and monitoring for anomalous adoption or controller activity can help reduce the impact of a successful attack.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago